KnowBe4 has released its 2024 Security Culture Report. The report examines how security measures really affect organizations and the way people act and feel at work. Segmented into a global and regional versions by North America, South America, Europe, Africa, Asia, and Oceania, the report takes into account regional nuances, behaviours, and attitudes towards cyber security in the workplace.
The 2024 Security Culture Report examines topics such as the varied cyber security maturity levels and what that means for organizations, the lack of communication in organizations and how that aids cyber attacks, as well as legislation and its implementation. It also covers the predicted increase in the quality and quantity of cyber attacks and the influence of AI.
The report looks at Security Culture Dimensions, where KnowBe4 systematically evaluates cyber security culture across seven distinct dimensions:
- Attitudes: the feelings and beliefs that employees have toward the security protocols and issues.
- Behaviors: the actions and activities of employees that have direct or indirect impact on the security of the organization.
- Cognition: employees’ understanding, knowledge, and awareness of security issues and activities.
- Communication: the quality of communication channels to discuss security-related topics, promote a sense of belonging and provide support for security issues and incident reporting.
- Compliance: the knowledge of written security policies and the extent that employees follow them.
- Norms: the knowledge of and adherence to unwritten rules of conduct in the organization.
- Responsibilities: how employees perceive their role as a critical factor in sustaining or endangering the security of the organization.
When looked at globally over the past five years changes in these areas were as follows:

Stand-out areas are:
- The drop in the Cognition dimension, showing that on average employees are less savvy when it comes to cyber security than they were five years ago.
- The increase in the Norms dimension, which is the knowledge of and adherence to unwritten rules of conduct in the organization.
- The general lack of change in many of the dimensions – this seems to show that cyber security culture has remained relatively static over the past five years, showing little in the way of improvement in most areas.






